Privacy & Security
As connected devices and apps collect ever more data about people, we study how to make these technologies trustworthy, transparent, and controllable by the people they affect. Our work spans both systems and human factors. On the consumer side, we led the design of the IoT Security and Privacy Label, studied how label complexity, the U.S. Cyber Trust Mark, and QR codes affect consumer comprehension and purchase decisions, and helped inform national IoT labeling efforts; this line of work was recognized with the Norm Hardy Prize from the Foresight Institute. For shared and always-on sensing, we explore mechanisms for transparency and control in smart homes, and ThingPoll, which lets the people sharing a space negotiate privacy settings together. For developers, we build tools such as Matcha and Honeysuckle that help create accurate privacy nutrition labels and in-app privacy notices. We also study the security of the broader device ecosystem, such as granular data ownership for IoT devices.
Projects

A 489-person survey of which smart-home privacy features, from mute buttons to microphone jammers, people actually trust and would use.

An Android Studio plugin that uses code analysis to help developers create accurate Google Play data safety labels.

A negotiation system that helps co-located people agree on privacy settings for shared IoT sensors, reaching agreement in 97.5% of scenarios.

A 518-person survey comparing IoT labels of three complexity levels, finding most buyers ignore QR codes and prefer details on the package.

An argument, backed by a 518-person study, that IoT labels should print key security and privacy facts next to the QR code.

An incentive-compatible study of 180 people measuring how much more they will pay for IoT devices with better security and privacy.

A measurement study from four African vantage points finding that 93% of popular Africa-visited websites critically depend on a third-party DNS, CDN, or CA.

Lets people near an IoT device temporarily claim co-ownership of its encrypted data, so no one can access it without their permission.

An in-home hub that runs developer-declared chains of fixed operators to minimize smart home data before it leaves for the cloud.

Models SmartThings apps as parameterized timed automata to find unsafe app interactions, uncovering 19 new violations across 86 apps.

Weekly snapshots of 1.4 million U.S. App Store apps show over half still lacked a privacy label months after Apple required one.

An observation and interview study of 12 iOS developers revealing common challenges in creating accurate Apple privacy nutrition labels.

Two surveys of 386 people on how they protect privacy in smart homes, finding a privacy diagnostics app the most wanted tool.

A two-layer IoT security and privacy label, designed with consumers and experts, that shows device data practices and protections before purchase.

An Android IDE plugin, build plugin, and library that generate in-app privacy notices from code annotations, tested with 12 developers.

A local hub that hosts and updates third-party libraries like OpenSSL for many IoT devices, instead of baking them into vendor firmware.

A 1,371-person survey measuring how each attribute on a proposed IoT privacy and security label shifts perceived risk and willingness to buy.

A 1,963-person U.S. survey experiment finding that individual differences matter more than app design for contact-tracing app adoption intention.

User interface designs for Android privacy settings built on developer-declared purposes, split between first-party and third-party data use.

A language for probabilistic, stateful network models that compiles to Markov chains to verify quantitative properties like latency and failure rates.

A measurement of Alexa top-100K websites showing 89% critically depend on third-party DNS, CDN, or certificate authority providers.

A Delphi study with 22 experts and interviews with 15 consumers that produced a two-layer privacy and security label for IoT devices.

An Android Studio plugin that prompts developers to annotate personal data use and flags privacy issues with quick fixes as they code.

A classifier that infers why an Android app sends data in each network request, reaching 84% average precision across 19 purposes.

Interviews with 24 IoT device owners on whether privacy and security shaped their purchases, plus their reactions to a prototype privacy label.

Mining templates from 120 million push notifications to automatically extract personal facts, such as names and purchases, without uploading personal data.

A measurement of the top 100K websites showing how many critically depend on a few third-party DNS, CDN, and certificate providers.

An Android programming framework that processes personal data as streams, making the granularity of data an app actually uses easy to analyze.

ProtectMyPrivacy for Android controls private data access per third-party library, since 30 libraries cause over half of accesses; deployed to 1,321 users.

Detects personal information leaked by smartphone apps by combining hashed traffic signatures crowdsourced from many users of the same app.

Static and dynamic analysis of decompiled Android code that infers why apps use location and contacts permissions, for over 90% of uses.

A personalized privacy assistant that recommends Android permission settings from a few questions; 72 field-study users adopted 78.7% of its recommendations.

Three online studies of fitness-wearable privacy notices finding that short notices inform users, but cutting expected practices can reduce awareness.

An overview of GIoTTO, an open-source IoT infrastructure stack led by CMU, and the security, privacy, and usability challenges it targets.

A position paper arguing the network must secure unpatchable IoT devices, using per-device micro-middleboxes driven by context-aware, cross-device policies.

A field study showing that nudges reporting how often apps accessed personal data led 95% of participants to reassess their app permissions.

An iOS tool that detects app access to private data and crowdsources protection decisions from 90,000+ users into per-app recommendations.